Splunk SOAR Certified Automation Developer — Question 48
Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)
Answer options
- A. Ping a host.
- B. Send email.
- C. Include in RSS feed.
- D. Run a script.
Correct answer: B, C, D
Explanation
The correct options are B, C, and D because these actions represent the built-in capabilities of a correlation search to notify users or execute additional processes. Option A, 'Ping a host,' is not a standard alert action for correlation searches.